Single Actor Bypassed Open VSX Security with “Disposable” Tools
ID: 0a45ca6a-6f65-5bd1-a004-42b48ff5e860
STIX ID: report--0a45ca6a-6f65-5bd1-a004-42b48ff5e860
Feed Name: securityonline.info
Security researcher Yeeth Security detected a sophisticated campaign on the Open VSX marketplace (Apr 27–28, 2026) in which a single threat actor published 16 malicious extensions that appeared unrelated but used string-fragment reconstruction and regenerated bundles with disposable publisher identities to hide runtime payload URLs; analysis tied samples to a common payload host (github.com/francesca898/dqwffqw) and the malicious infrastructure remained active at time of reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
